claw is an AI agent skill, created by cto1 and published at openclaw/skills. ClawSecure audited claw across 3 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 21 findings concentrate in Command Injection, Policy Violation and Permissions Manifest, including Detects command injection patterns in agent skills: shell operators,... and Detects command injection patterns in agent skills: shell operators,.... 19 were rated high or critical severity.
Is claw safe?
ClawSecure audited claw and assigned a security score of 0/100 (High Risk), identifying 21 findings across Command Injection and Policy Violation. Review the findings below before installing.
What did ClawSecure find in claw?
ClawSecure identified 21 findings in claw, concentrated in Command Injection, Policy Violation and Permissions Manifest. 19 were rated high or critical severity. The most severe include Detects command injection patterns in agent skills: shell operators,... and Detects command injection patterns in agent skills: shell operators,....
How was claw audited?
ClawSecure ran claw through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 3 files from openclaw/skills.
What does a score of 0 mean?
ClawSecure assigned claw a security score of 0/100, placing it in the High Risk range. This is driven by 21 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for claw
ClawSecure detected 21 security findings in claw, spanning Command Injection, Policy Violation, Permissions Manifest and Code Injection.
- critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:113. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:150. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:159. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:186. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:209. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:241. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:250. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:259. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:275. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:300. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:309. - critical · Detects command injection patterns in agent skills: shell operators,.... Command Injection finding detected in
SKILL.md:328.
Showing the 12 highest-severity of 21 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for claw
Harden command execution
Resolve policy violations
Add a config.json permissions manifest
Related Security Research
Why Generic Scanners Fail at AI Agent Security→Understanding Our 3-Layer Audit Protocol→Related AI Agent Security Audits
Scanned on February 7, 2026. claw is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.